Sample viewer

vx.netlux.org/Virus.DOS.Next.1721

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:28.651536381Z 240 PC: 12a52 | UNKNOWN!
2018-12-17T22:27:28.652864956Z 44 PC: 12a62 | Get time 0x12a62: cmp cl, 5
0x12a65: jne 0x12a6f
0x12a67: mov byte ptr cs:[si + 0x1b6], 1
0x12a6d: nop
0x12a6e: nop
0x12a6f: push ds
0x12a70: mov bx, es
0x12a72: dec bx
0x12a73: mov ds, bx
0x12a75: xor di, di
0x12a77: cmp byte ptr [di], 0x5a
0x12a7a: jne 0x12ab5
0x12a7c: inc di
0x12a7d: mov bx, 0xf2
0x12a80: sub word ptr [di + 2], bx
0x12a83: sub word ptr [di + 0x11], bx
0x12a86: inc di
0x12a87: mov es, word ptr [di + 0x10]
0x12a8a: xor ax, ax
0x12a8c: mov ds, ax

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":4887,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:11.299918158Z 240 PC: 12a52 | UNKNOWN!
2018-12-25T11:53:11.301394102Z 44 PC: 12a62 | Get time 0x12a62: cmp cl, 5
0x12a65: jne 0x12a6f
0x12a67: mov byte ptr cs:[si + 0x1b6], 1
0x12a6d: nop
0x12a6e: nop
0x12a6f: push ds
0x12a70: mov bx, es
0x12a72: dec bx
0x12a73: mov ds, bx
0x12a75: xor di, di
0x12a77: cmp byte ptr [di], 0x5a
0x12a7a: jne 0x12ab5
0x12a7c: inc di
0x12a7d: mov bx, 0xf2
0x12a80: sub word ptr [di + 2], bx
0x12a83: sub word ptr [di + 0x11], bx
0x12a86: inc di
0x12a87: mov es, word ptr [di + 0x10]
0x12a8a: xor ax, ax
0x12a8c: mov ds, ax